IA Concepts Week 1

information systems security

 

Lesson 1 Information systems security

 

CSF - cyber security framework - identifies, detects, protects, respond, and recover so that an organization becomes familiar with to uphold (CIA)confidentiality, integrity, and availability.

Key concepts

  • Information system security concepts

    • Internet, world wide web.

    • Risk - likely hood that something bad will happen to an asset, threat -  any action that could damage and asset, vulnerability - a weakness that allows a threat to be a risk(risk = threat x vulnerability

    • information system - hardware operating system and application software that work together to collect data.

  • Confidentiality, integrity, and availability (CIA)

    • Confidentiality - Private data of individuals, intellectual property of businesses, national security for countries and governments. Cryptography, encryption, and ciphertext.

    • Integrity - maintain valid, uncorrupted, and accurate information.

    • Availability - in the context of information security, the amount of time users can use a system, application, and data. Availability Time measurements -  uptime, downtime, mean time for failure, mean time to repair, mean time between failures, recovery time objective(optimal time to get said thing back up).

 

  • The seven domains of an IT infrastructure

    • User domain, workstation domain, LAN(Local Area Network) domain, LAN-to-WAN(Wide Area Network) Domain, WAN domain, Remote access domain, System/Application domain.

    • Roles and Tasks, Responsibility, and accountability for each domain(CHATGPT)

 

  • The weakest link in the security of an IT infrastructure

    • The user is the weakest link in security

  • IT security policy framework and data classification standard.

    • Policy, standard, procedures, and guidelines

    • Policy hierarchy

    • Data classification standards